First published: Sun Dec 10 2023(Updated: )
A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247343.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6650 is classified as a problematic vulnerability affecting the SourceCodester Simple Invoice Generator System 1.0.
To mitigate CVE-2023-6650, it is recommended to sanitize user input and implement proper output encoding in the login.php file.
CVE-2023-6650 is a cross-site scripting (XSS) vulnerability that can be exploited through the cashier argument.
CVE-2023-6650 affects version 1.0 of the SourceCodester Simple Invoice Generator System.
Yes, CVE-2023-6650 can be exploited remotely through crafted requests targeting the login.php file.